Skip to content

Install the agent

Three steps on Linux, Windows, a Mac or a Kubernetes cluster: get a token in Gryphon, install the agent, and give it the token. It connects out to Gryphon, so the machine needs no open port and no certificate.

Before you start

The agent connects to Gryphon, not the other way round. It opens one connection out to Gryphon over HTTPS and keeps it open, and Gryphon sends its checks down that connection. The machine needs no open port, no address of its own and no certificate: if it can reach a website, it can reach Gryphon. It proves which host it is with a token you get in Gryphon.

Checks from outside — websites, certificates, ping, ports, DNS and domains — need no agent. Install it for what only the machine can see: disk, memory, CPU and load, databases, Docker, scripts and files, and checks on your private network.

What you'll need

Administrator rights on the machine: sudo, or PowerShell's Run as administrator. And the machine must be able to make an HTTPS connection out to Gryphon, as it would to any website; more on that if a firewall or a proxy is in the way.

One agent per machine

Install it on the machine you mean to watch, not in a container on it: its disk, memory and CPU readings are the machine's. One agent covers the machine, every container on it, and any number of checks sent to it. Each machine is a host of its own in Gryphon, with a token of its own. A Kubernetes cluster is the exception: one agent, inside it, for the whole cluster.

Open source

The agent is open source, under the MIT licence, and every download below is built from that code. Read it on GitHub before you install it.

The three steps

  1. 1 Get a token from the host's page in Gryphon. It is shown once.
  2. 2 Install the agent on Linux, macOS, Windows or in a Kubernetes cluster. Your system's section covers steps 2 and 3.
  3. 3 Give it the token. It checks the token with Gryphon, starts, and the host's page says it is connected.

1 Get a token in Gryphon

  1. 1 In Gryphon, open Hosts and choose the machine, or Add host and save it. This takes the account's owner, or a member the owner allows to manage hosts.
  2. 2 On its Host tab, under Agent, choose Connect an agent.
  3. 3 Copy the token it shows. It is shown only this once: Gryphon keeps nothing it could show again. Keep the page open until step 3 is done.

Lost it? Choose Replace token on the same page. The old token stops working at once, and an agent using it is disconnected.

Linux

One static binary for amd64 and arm64, packaged with a hardened systemd service. The packages and the install script put the same program, settings file and service in place, and the program is called gryphon-agent.

2 Install it

Pick the method that suits the machine. Each one downloads the release's checksums and checks the download against them before installing anything.

Debian and Ubuntu

VERSION=1.1.28
BASE=https://github.com/gocodedotca/gryphon-agent/releases/download/v$VERSION
ARCH=$(dpkg --print-architecture)
curl -fLO $BASE/gryphon-agent_${VERSION}_$ARCH.deb
curl -fLO $BASE/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
sudo apt install ./gryphon-agent_${VERSION}_$ARCH.deb

Fedora, RHEL, Rocky and Alma

VERSION=1.1.28
BASE=https://github.com/gocodedotca/gryphon-agent/releases/download/v$VERSION
ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -fLO $BASE/gryphon-agent_${VERSION}_$ARCH.rpm
curl -fLO $BASE/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
sudo dnf install ./gryphon-agent_${VERSION}_$ARCH.rpm

Any other Linux with systemd

An install script puts the same program, settings file and service in place from the plain archive. Read it before running it as root.

curl -fsSLO https://raw.githubusercontent.com/gocodedotca/gryphon-agent/main/deploy/agent/install.sh
less install.sh
sudo sh install.sh

It installs the latest release, or the one you name (sudo sh install.sh v1.1.28). Run it again to update.

Without systemd, or by hand

The archive holds the program and nothing needs installing. This asks for the token from step 1, saves it beside the program readable by you alone, and runs the agent in the foreground; run it under whatever supervises your services once it works.

VERSION=1.1.28
BASE=https://github.com/gocodedotca/gryphon-agent/releases/download/v$VERSION
ARCH=$(uname -m | sed 's/x86_64/amd64/; s/aarch64/arm64/')
curl -fLO $BASE/gryphon-agent_${VERSION}_linux_$ARCH.tar.gz
curl -fLO $BASE/SHA256SUMS
sha256sum --ignore-missing -c SHA256SUMS
tar -xzf gryphon-agent_${VERSION}_linux_$ARCH.tar.gz
read -rsp "Token: " TOKEN; echo
(umask 077; printf '%s\n' "$TOKEN" > agent_key); unset TOKEN
GWC_KEY_FILE=./agent_key ./gryphon-agent

The token goes in a file or the environment, never on the command line, where every user on the machine could read it. ./gryphon-agent -help lists the other settings. Skip step 3: the agent is already connecting.

3 Give it the token

Installed, it is off until it has a token. This asks for the token from step 1 — paste it; it is not shown as you do — checks it with Gryphon, saves it where only root can read it, and starts the agent. It starts with the machine from then on.

sudo gryphon-agent enrol

Within a few seconds the host's page in Gryphon says Connected. If it does not, these say whether the agent is running, and why not:

systemctl status gryphon-agent
sudo journalctl -u gryphon-agent -n 50

Once the host's page in Gryphon says Connected, add the agent's checks under Manage Services: disk, memory, CPU and load, databases, Docker, scripts, files, and HTTP, ping and TCP from inside your network.

macOS

Gryphon Agent is the same agent as a menu bar app: no Dock icon, no window, no terminal. macOS 12 or later, on Apple silicon or Intel, signed with our Developer ID and notarized by Apple.

2 Install it

With Homebrew

brew install --cask gocodedotca/gryphon/gryphon-agent

Or download the app

Open the disk image and drag Gryphon Agent to Applications.

3 Give it the token

Open Gryphon Agent from Applications. It appears in the menu bar, saying it has no token yet. Choose Enter Token…, paste the token from step 1 and choose Connect. The first line of its menu says connected, and so, within a few seconds, does the host's page in Gryphon.

Choose Open at Login so it starts with the Mac. A Mac is watched only while it is awake. The agent's log is ~/Library/Logs/Gryphon Agent.log.

Once the host's page in Gryphon says Connected, add the agent's checks under Manage Services: disk, memory, CPU and load, databases, Docker, scripts, files, and HTTP, ping and TCP from inside your network.

Windows

The same agent as a Windows service, for Windows 10 and 11 and Windows Server 2016 or later, on x64 or Arm. One command sets up the service and a settings folder only administrators can change, and another gives it its token.

Use one PowerShell window for both steps, opened as administrator: Start, type PowerShell, then choose Run as administrator.

2 Install it

Download and check it

This works in a temporary folder, picks x64 or Arm for you, and stops if the download does not match the release's checksums.

$ProgressPreference = "SilentlyContinue"
Set-Location $env:TEMP
$Version = "1.1.28"
$Arch = "amd64"
if ("$env:PROCESSOR_ARCHITECTURE $env:PROCESSOR_ARCHITEW6432" -match "ARM64") { $Arch = "arm64" }
$Base = "https://github.com/gocodedotca/gryphon-agent/releases/download/v$Version"
$Zip = "gryphon-agent_${Version}_windows_$Arch.zip"
Invoke-WebRequest "$Base/$Zip" -OutFile $Zip
Invoke-WebRequest "$Base/SHA256SUMS" -OutFile SHA256SUMS
$Want = (Select-String -Path SHA256SUMS -SimpleMatch $Zip).Line.Split(" ")[0]
if ((Get-FileHash $Zip).Hash -ne $Want) { throw "checksum mismatch" }
Expand-Archive $Zip -DestinationPath gryphon-agent -Force

Install the service

In the same window. It copies the program to C:\Program Files\Gryphon Agent, makes C:\ProgramData\Gryphon for its token and settings, and registers the GryphonAgent service:

.\gryphon-agent\gryphon-agent.exe service install

3 Give it the token

In the same window. This asks for the token from step 1 — paste it; it is not shown as you do — checks it with Gryphon, saves it where only administrators and the service can read it, and starts the service. It starts with the machine from then on.

& 'C:\Program Files\Gryphon Agent\gryphon-agent.exe' enrol

Within a few seconds the host's page in Gryphon says Connected. If it does not, these say whether the service is running, and why not:

Get-Service GryphonAgent
Get-WinEvent -FilterHashtable @{LogName="Application"; ProviderName="GryphonAgent"} -MaxEvents 20

Once the host's page in Gryphon says Connected, add the agent's checks under Manage Services: disk, memory, CPU and load, databases, Docker, scripts, files, and HTTP, ping and TCP from inside your network.

Kubernetes

One agent watches the whole cluster, running inside it as a pod and reading the cluster's own API: workloads, applications, nodes, crash-looping pods and CronJobs. In Gryphon the cluster is one host whose kind is A Kubernetes cluster; make it, then take its token as in step 1. Kubernetes checks are on the Pro and Teams plans.

2 Install it, with the token

With kubectl pointed at the cluster, put the token from step 1 in a Secret and apply the manifest:

kubectl create namespace gryphon
kubectl -n gryphon create secret generic gryphon-agent-token --from-literal=token=<token>
kubectl apply -f https://github.com/gocodedotca/gryphon-agent/releases/download/v1.1.28/gryphon-agent.yaml

Within a few seconds of the pod starting, the host's page in Gryphon says Connected and names the cluster's version. If it does not, these say why:

kubectl -n gryphon get pods
kubectl -n gryphon logs deployment/gryphon-agent

What it may read

Only what its ClusterRole grants: to get and list nodes, namespaces, pods, Deployments, StatefulSets, DaemonSets, ReplicaSets, Jobs and CronJobs. It cannot read Secrets or ConfigMaps, open a shell in a pod, read logs, or change anything. The manifest is short; read it before you apply it.

One namespace at a time

Where cluster-wide access is not an option, apply gryphon-agent-namespaced.yaml instead, and gryphon-agent-role.yaml in each namespace to watch, with kubectl apply -n shop -f. The nodes check needs cluster-wide access, and says so.

Inside and outside

The agent's HTTP, TCP and database checks run from its pod, so they can name a Service by its name in the cluster, such as web.shop.svc.cluster.local. Give the host the public address in front of the cluster, its Ingress or load balancer, and Gryphon checks that from outside as well, certificate included.

What it runs as

One pod, as a user with no privileges, on a read-only file system, with every Linux capability dropped. The image is ghcr.io/gocodedotca/gryphon-agent, for amd64 and arm64, built from the same open source code as every other download. It opens no port and needs no Service or Ingress.

The network

The agent makes one connection, out, to https://gryphon.gocode.ca on port 443 — HTTPS, kept open as a WebSocket — and reconnects by itself if it drops. Nothing connects to the machine, so there is no port to open, no address to publish, and nothing for a stranger on the internet to knock on.

Troubleshooting

Enrolling says “Gryphon refused this token”
The token was copied short, or it has been replaced since. Copy it again, whole, from the dialog in step 1; if that is closed, choose Replace token on the host's page and enrol with the new one.
Enrolling says “Cannot reach Gryphon”
The machine cannot make the connection out. Check the network: an outbound firewall, a proxy that needs HTTPS_PROXY, or no route to the internet at all.
The host's page says “Waiting for the agent to connect”
The token was issued and no agent has used it yet: step 3 was not run, or the agent is not running. Step 3's last commands say why.
The host's page says “Not connected”, and checks say “Agent: not connected”
The agent was connected and has stopped: the machine is off or asleep, the agent was stopped, or its connection out is blocked. It reconnects by itself once it can. A Mac is watched only while it is awake and its agent is on.
The Mac's menu says “the token was refused”
Its token was replaced, or its host deleted. Choose Enter Token… with a new one from the host's page.
The host's page says the token is in use on more than one machine
Two machines were given the same token, and they keep taking the connection from each other. Each machine needs a host of its own in Gryphon. Replace the token, give the new one to this machine only, and add a host for the other.
A check says “update the agent”
The check is newer than the agent on that machine. Update it; the token and settings are kept.

Optional settings

Scripts, files, Docker and ICMP ping are off until you turn them on, and a web proxy is set here too (HTTPS_PROXY=http://proxy.example.com:3128). Restart the agent after any change.

  • Linux: settings go in /etc/gryphon/agent.env, which updates leave alone. Changes to the service itself go in a drop-in, made with sudo systemctl edit gryphon-agent, because updates replace the unit file. Then sudo systemctl restart gryphon-agent.
  • Windows: the same settings, in C:\ProgramData\Gryphon\agent.env, which updates leave alone. Then Restart-Service GryphonAgent.
  • Mac: Edit Settings… opens its settings file, where scripts and files are scripts_dir and watch_dirs. Then Turn Off and Turn On.

Script checks

Name a folder of programs; Gryphon can run only what is in it, by file name. On Linux it must be owned by root and writable by nobody else. On Windows, use the scripts folder install made, put .ps1, .bat, .cmd or .exe files in it, and name them in Gryphon with their extension. Create them there rather than moving them in, so they take its permissions.

Linux, in agent.env
GWC_SCRIPTS_DIR=/etc/gryphon/scripts
Windows, in agent.env
GWC_SCRIPTS_DIR=C:\ProgramData\Gryphon\scripts

File checks

Name the folders the agent may look in: colons between them on Linux, semicolons on Windows. A file freshness check's path must be inside one of them. The agent only lists them, never opens a file. On Linux it runs as its own unprivileged user, so the folders must be listable by others, or add their group with SupplementaryGroups= in a drop-in.

Linux, in agent.env
GWC_WATCH_DIRS=/var/backups:/srv/exports
Windows, in agent.env
GWC_WATCH_DIRS=D:\Backups;C:\ProgramData\MyApp\exports

Docker

For the container and Swarm checks. On Linux, run the read-only socket proxy the package puts in /usr/share/doc/gryphon-agent/docker-socket-proxy.yml (also in the release archive, under deploy/agent), then point the agent at it. On Windows the agent reaches Docker Desktop through its named pipe, which only administrators and the docker-users group may open, so add the service to that group.

Linux, in agent.env
GWC_DOCKER_SOCKET=tcp://127.0.0.1:2375
Windows, in PowerShell as administrator
net localgroup docker-users "NT SERVICE\GryphonAgent" /add

Ping by ICMP

Without it the ping check probes TCP ports 443, 80 and 22 instead. On Linux, allow it in the drop-in. Windows only lets an administrator send a ping, so there the ping check always probes the ports. Windows has no load average either: load there is an estimate from the processor queue, and CPU is the better check.

Linux, in the drop-in
[Service]
CapabilityBoundingSet=CAP_NET_RAW
AmbientCapabilities=CAP_NET_RAW

Updating

On Linux, install the newer package over the old one, or run the install script again. A running agent is restarted on the new version, with its token and settings kept. On Windows, run step 1 again with the newer release, in an administrator PowerShell, which does the same. On a Mac, brew upgrade --cask gryphon-agent, or download the new app over the old one; its menu shows Update available when there is one.

Removing

sudo apt remove gryphon-agent or sudo dnf remove gryphon-agent stops it and removes it. The token stays in /etc/gryphon, so a reinstall still connects as the same host; delete the directory to forget it. apt leaves agent.env there too, and dnf keeps it only if you changed it, as agent.env.rpmsave. After the install script, sudo systemctl disable --now gryphon-agent, then delete /usr/bin/gryphon-agent and /etc/systemd/system/gryphon-agent.service. On Windows, service uninstall with the installed program removes the service; delete C:\ProgramData\Gryphon and C:\Program Files\Gryphon Agent to forget the rest. On a Mac, turn off Open at Login, quit the app and move it to the Trash, or brew uninstall --cask --zap gryphon-agent. Deleting the host in Gryphon disconnects its agent and refuses its token from then on.

Fourteen days free. Then from $4.99 a month.

The agent, the dashboard, the apps and every check but the five for Kubernetes are in every plan. The plans differ in how much you watch, how often, from where, and how many people and status pages they include. Compare the plans. Cancel any time.

Already have an account? Sign in